2023 CVE Vulnerabilities
31,397 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-47253 | CRITICAL | 9.8 | 14.4% | Nov 6, 2023 | Qualitor through 8.20 allows remote attackers to execute arbitrary code via PHP code in the html/ad/adpesquisasql/reques... |
| CVE-2023-38407 | HIGH | 7.5 | 0.9% | Nov 6, 2023 | bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast pars... |
| CVE-2023-38406 | CRITICAL | 9.8 | 0.9% | Nov 6, 2023 | bgpd/bgp_flowspec.c in FRRouting (FRR) before 8.4.3 mishandles an nlri length of zero, aka a "flowspec overflow." |
| CVE-2023-4625 | MEDIUM | 5.3 | 0.9% | Nov 6, 2023 | Improper Restriction of Excessive Authentication Attempts vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F/i... |
| CVE-2023-32840 | MEDIUM | 6.5 | 0.2% | Nov 6, 2023 | In modem CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalatio... |
| CVE-2023-32839 | MEDIUM | 6.7 | 0.1% | Nov 6, 2023 | In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalati... |
| CVE-2023-32838 | MEDIUM | 6.7 | 0.1% | Nov 6, 2023 | In dpe, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalati... |
| CVE-2023-32837 | HIGH | 7.8 | 0.1% | Nov 6, 2023 | In video, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of ... |
| CVE-2023-32836 | MEDIUM | 6.7 | 0.1% | Nov 6, 2023 | In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of p... |
| CVE-2023-32835 | MEDIUM | 6.7 | 0.1% | Nov 6, 2023 | In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local escalation of privi... |
| CVE-2023-32834 | MEDIUM | 6.7 | 0.1% | Nov 6, 2023 | In secmem, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege... |
| CVE-2023-32832 | HIGH | 7 | 0.1% | Nov 6, 2023 | In video, there is a possible memory corruption due to a race condition. This could lead to local escalation of privileg... |
| CVE-2023-32825 | MEDIUM | 5.5 | 0.1% | Nov 6, 2023 | In bluethooth service, there is a possible out of bounds reads due to improper input validation. This could lead to loca... |
| CVE-2023-32818 | MEDIUM | 6.7 | 0.1% | Nov 6, 2023 | In vdec, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege... |
| CVE-2023-20702 | HIGH | 7.5 | 1.1% | Nov 6, 2023 | In 5G NRLC, there is a possible invalid memory access due to lack of error handling. This could lead to remote denial of... |
| CVE-2023-46802 | MEDIUM | 5.5 | 0.2% | Nov 6, 2023 | e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configurat... |
| CVE-2023-47272 | MEDIUM | 6.1 | 0.6% | Nov 6, 2023 | Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used fo... |
| CVE-2023-47271 | MEDIUM | 5.3 | 0.6% | Nov 6, 2023 | PKP-WAL (aka PKP Web Application Library or pkp-lib) before 3.3.0-16, as used in Open Journal Systems (OJS) and other pr... |
| CVE-2023-47260 | MEDIUM | 6.1 | 0.4% | Nov 5, 2023 | Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS via thumbnails. |
| CVE-2023-47259 | MEDIUM | 6.1 | 0.4% | Nov 5, 2023 | Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in the Textile formatter. |
| CVE-2023-47258 | MEDIUM | 6.1 | 0.4% | Nov 5, 2023 | Redmine before 4.2.11 and 5.0.x before 5.0.6 allows XSS in a Markdown formatter. |
| CVE-2023-47249 | MEDIUM | 6.5 | 0.5% | Nov 5, 2023 | In International Color Consortium DemoIccMAX 79ecb74, a CIccXmlArrayType:::ParseText function (for unsigned short) in Ic... |
| CVE-2023-46981 | CRITICAL | 9.8 | 1.1% | Nov 5, 2023 | SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted scrip... |
| CVE-2023-46964 | MEDIUM | 6.1 | 0.5% | Nov 5, 2023 | Cross Site Scripting (XSS) vulnerability in Hillstone Next Generation FireWall SG-6000-e3960 v.5.5 allows a remote attac... |
| CVE-2023-46963 | MEDIUM | 5.3 | 0.5% | Nov 4, 2023 | An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attack... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now